Back to CVE List

CVE-2026-28510

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.9 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Vulnerability Description

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-302
Source
NVD
Vendor
elabftw
Product
elabftw

External References

Discussion (0)

Add Comment

No comments yet. Be the first!